๐Ÿ” CVE Alert

CVE-2026-62943

UNKNOWN 0.0

btrbk: SSH Command Filter Bypass in ssh_filter_btrbk.sh

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the complete command. A user restricted through an authorized_keys forced command can append a trailing pipe command after a valid btrbk command prefix, bypassing the allowlist and executing arbitrary commands with the privileges of the backup-target SSH account. Deployments that do not use ssh_filter_btrbk.sh in authorized_keys are not affected. This issue is fixed in version 0.32.7.

CWE CWE-78
Vendor digint
Product btrbk
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for digint btrbk

Be the first to know when new unknown vulnerabilities affecting digint btrbk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

digint / btrbk
>= 0.29.0, < 0.32.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/digint/btrbk/security/advisories/GHSA-pf45-7g54-65h5 github.com: https://github.com/digint/btrbk/commit/29ca3c093205395bdeb9dd98677ab4139c458aec github.com: https://github.com/digint/btrbk/releases/tag/v0.32.7